Floating Form Button Security & Risk Analysis

wordpress.org/plugins/floating-form-button

The "Floating Form Button" displayes an fixed contact button on the bottom right of the screen. It opens an small popup form above the butto …

10 active installs v0.9.1 PHP 5.5+ WP 4.6+ Updated Aug 11, 2020
floating-bubblefloating-bubble-speechfloating-buttonfloating-form-bubblefloating-form-button
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Floating Form Button Safe to Use in 2026?

Generally Safe

Score 85/100

Floating Form Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the "floating-form-button" plugin v0.9.1 exhibits a generally strong security posture. The absence of any detected dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly positive. Furthermore, the high percentage of properly escaped output signals good development practices for preventing cross-site scripting (XSS) vulnerabilities.

However, there are notable areas for improvement. The complete lack of nonce checks and capability checks across all entry points (though the attack surface is currently zero) represents a significant theoretical risk. If any new entry points are introduced in future versions without these security measures, the plugin would be highly vulnerable to CSRF and unauthorized action exploits. The taint analysis showing zero flows is also positive, but this is likely due to the limited scope or no sensitive data flows being present in this version.

The plugin's vulnerability history is exceptionally clean, with no recorded CVEs, which is a strong indicator of its past security. This, combined with the current static analysis findings, suggests a responsible development approach. The overall risk is low for the current version due to the lack of exploitable attack surface and known vulnerabilities, but the absence of fundamental security checks like nonces and capability checks presents a latent risk for future development.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • Some output not properly escaped
Vulnerabilities
None known

Floating Form Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Floating Form Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped7 total outputs
Attack Surface

Floating Form Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initfloating-form-button.php:35
actionadmin_menufloating-form-button.php:36
actionadmin_enqueue_scriptsfloating-form-button.php:37
actionwp_enqueue_scriptsfloating-form-button.php:38
actionwp_footerfloating-form-button.php:39
Maintenance & Trust

Floating Form Button Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedAug 11, 2020
PHP min version5.5
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Floating Form Button Developer Profile

Plugin Devs

14 plugins · 18K total installs

78
trust score
Avg Security Score
85/100
Avg Patch Time
60 days
View full developer profile
Detection Fingerprints

How We Detect Floating Form Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/floating-form-button/assets/css/bubble.css/wp-content/plugins/floating-form-button/admin/assets/css/style.css/wp-content/plugins/floating-form-button/assets/css/style.css/wp-content/plugins/floating-form-button/assets/js/script.js
Script Paths
/wp-content/plugins/floating-form-button/assets/js/script.js
Version Parameters
floating-form-button/assets/css/bubble.css?ver=floating-form-button/admin/assets/css/style.css?ver=floating-form-button/assets/css/style.css?ver=floating-form-button/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wb_ffb_menu_pagewb_ffb_bubble_containerwb_ffb_buble_boxwb_ffb_bubblewb_ffb_bubble_square_bottom_leftwb_ffb_bubble_square_bottom_rightwb_ffb_bubble_square_bottom_plainwb_ffb_bubble_round_bottom_left+3 more
Data Attributes
name="wb_ffb_form_shortcode"name="wb_ffb_bubble_style"name="wb_ffb_custom_css"
FAQ

Frequently Asked Questions about Floating Form Button